Legal · Privacy Policy
The least data that works.
The instruments collect nothing — they run on your machine. This site collects only what a newsletter, an account, and a purchase actually require, and tells you exactly who processes it.
Last updated · 14 June 2026
1. The short version
PM Vault is built privacy-first. The instruments you buy are offline, client-side software: they create no account, collect no telemetry, and transmit nothing. Your project data never reaches us. The only personal data we ever hold is the small amount this website needs — to email you, to sign you in to your account, and to record what you bought so you can download it and recover your licence key.
2. What we collect, and why
| Data | Why | Basis (GDPR) |
|---|---|---|
| Newsletter email | To send the founding-list updates you asked for. One-click unsubscribe in every email. | Consent |
| Account email | To sign you in (a one-time link by email — we store no password) and show your purchases. | Contract |
| Purchase & licence records | Order reference, product, and your licence key, so you can download what you bought and restore your key. | Contract |
| Essential session cookie | Keeps you signed in to your account. No tracking, advertising, or analytics cookies are set. | Strictly necessary |
3. Who processes your data
We keep the list of processors short and name them plainly:
- Paddle — our payment processor and merchant of record. Paddle handles checkout, takes payment, applies tax, and issues your receipt. We never see or store your card details. Paddle processes your purchase data under its own privacy notice.
- Cloudflare — hosts this site and the account/download service (including the database that stores your account email and licence records). Data is processed in Cloudflare's network.
- MailerLite — sends the newsletter to subscribers who opt in.
- First-party analytics (no third party) — we record cookieless, aggregate usage events (page views and a few interactions, such as opening a demo) on our own infrastructure, hosted with Cloudflare. We store no cookies, no IP addresses, and no personal profiles — only an event name, the page, and an approximate country — so the data cannot be used to identify you.
- Our transactional email provider — delivers your one-time sign-in links and purchase emails.
We do not sell your data, and we do not share it beyond the processors above, except where the law requires it.
4. Payments
When checkout opens, all payments are handled by Paddle as merchant of record. Card and billing details are entered with Paddle, not with us — we receive only the order reference, the product, and the email you used, so we can grant your download and licence. Paddle's buyer terms and privacy notice apply to the payment itself.
5. How long we keep it
Newsletter email: until you unsubscribe. Account and purchase records: for as long as you hold a licence, plus the period we are required to keep transaction records for tax and accounting. Sign-in links expire within minutes and are single-use. You can ask us to delete your account at any time (see §7).
6. Security
The site serves over HTTPS with a strict content-security policy. We store no passwords. Sign-in is by single-use, short-lived email link. Account sessions use a secure, http-only cookie. Downloads are served through short-lived, signed links tied to your purchase. Licence keys are stored to let you recover them; the private key that signs licences never leaves our server and is never shipped in any product.
7. Your rights
Wherever you live, you can ask us to show you the data we hold, correct it, delete it, or export it, and you can object to or withdraw consent for the newsletter. Write to [email protected] and a person will action it. If you are in the UK/EU and think we have got something wrong, you may also complain to your local data-protection authority.
8. Children
PM Vault is a professional tool and is not directed at anyone under 16. We do not knowingly collect data from children.
9. Changes
We will update this page as the product and the law evolve; the date above changes when we do.
10. Contact
Questions about privacy, or a data request: [email protected].